OpenStack, LLC.

Short Name: [None Entered]
Previous Names: [None Entered]
URL: [None Entered]
Email: [None Entered]
Security URL: [None Entered]
Security Email: [None Entered]
Knowledge Base: [None Entered]
Notes: [No Notes]

Vulnerabilities by Vendor Product

OpenStack, LLC.

OpenStack, LLC.
OpenStack Compute Watch-list
Unspecified
OSVDB ID: 88419 OpenStack Compute (Nova) LVM-Backed Image Local Information Disclosure
Essex (2012.1)
OSVDB ID: 90657 OpenStack Compute (Nova) VNC Proxy VM Deletion Handling Console Token Reuse
Folsom (2012.2
OSVDB ID: 90657 OpenStack Compute (Nova) VNC Proxy VM Deletion Handling Console Token Reuse
OpenStack Object Storage (swift) Watch-list
1.6.0
OSVDB ID: 86581 OpenStack Object Storage (swift) Module for Python loads Function memcached Pickle Object Handling Remote Code Execution
Glance Watch-list
Unspecified
OSVDB ID: 91304 OpenStack Glance Cached Image Request Handling Backend Credentials Disclosure
OpenStack Keystone Watch-list
2012.1
OSVDB ID: 84334 OpenStack Keystone Password Change Token Persistance
OSVDB ID: 84336 OpenStack Keystone Token Expiration Mechanism New Token Request Parsing Token Expiration Time Extension
2012.1
OSVDB ID: 84335 OpenStack Keystone Token Expiration Mechanism Disabled User Token Invalidation Failure
2012.1
Essex (2012.1)
OSVDB ID: 85113 OpenStack Keystone User Tenant Update Handling Admin API Access Restriction Bypass
2012.1.2
OSVDB ID: 85484 OpenStack Keystone Role Granting / Revoking Token Role Persistance
2012.1
OSVDB ID: 85780 OpenStack Keystone OS-KSADM Service User Tenant API X-Auth-Token Verification Access Restriction Bypass
2012.1.2
OSVDB ID: 85780 OpenStack Keystone OS-KSADM Service User Tenant API X-Auth-Token Verification Access Restriction Bypass
2012.1
OSVDB ID: 85823 OpenStack Keystone Disabled Tenant Authentication Persistance
2012.1.2
OSVDB ID: 88337 OpenStack Keystone Permission Weakness EC2 Admin Secret Key Local Disclosure
Unspecified
OSVDB ID: 92594 OpenStack Keystone keystone.conf Permission Weakness admin_token Local Disclosure
OpenStack Dashboard (Horizon) Watch-list
2012.1
OSVDB ID: 81742 OpenStack Dashboard (Horizon) Guest Console Local XSS
OSVDB ID: 81741 OpenStack Dashboard (Horizon) Session ID Reuse Session Fixation Weakness
2012.2
OSVDB ID: 81741 OpenStack Dashboard (Horizon) Session ID Reuse Session Fixation Weakness
2012.1
Essex (2012.1)
Essex (2012.1)
OSVDB ID: 85114 OpenStack Dashboard (Horizon) auth/login/ next Parameter Arbitrary Site Redirect
OpenStack Glance Watch-list
2012.2
OSVDB ID: 89739 OpenStack Glance Endpoint Handling Error Message Swift Credentials Disclosure
2012.1
OSVDB ID: 89739 OpenStack Glance Endpoint Handling Error Message Swift Credentials Disclosure
OpenStack Compute (Nova) Watch-list
2012.1
2012.1
OSVDB ID: 81641 OpenStack Compute (Nova) Security Group Rules Saturation Resource Exhaustion Remote DoS
OSVDB ID: 83539 OpenStack Compute (Nova) Disk Image Remote Arbitrary File Injection
OSVDB ID: 83540 OpenStack Compute (Nova) Crafted Instance Request Arbitrary File Corruption
2011.3
OSVDB ID: 82736 OpenStack Compute (Nova) EC2 / OS API Incorrect Case Definition Protocol Handling Security Group Rules Bypass
2012.1
OSVDB ID: 82736 OpenStack Compute (Nova) EC2 / OS API Incorrect Case Definition Protocol Handling Security Group Rules Bypass
2012.2
OSVDB ID: 82736 OpenStack Compute (Nova) EC2 / OS API Incorrect Case Definition Protocol Handling Security Group Rules Bypass
2012.1
2012.1
2012.2
OSVDB ID: 83540 OpenStack Compute (Nova) Crafted Instance Request Arbitrary File Corruption
2012.3
OSVDB ID: 83540 OpenStack Compute (Nova) Crafted Instance Request Arbitrary File Corruption
Unspecified
OSVDB ID: 83735 OpenStack Compute (Nova) Nova Scheduler Node scheduler_hints Parameter Request Parsing Remote DoS
2011.3
OSVDB ID: 78274 OpenStack Compute (Nova) Tenant Access Restriction Weakness API Request Parsing Remote Data Manipulation
Nova Watch-list
Unspecified
OSVDB ID: 91303 OpenStack Nova Fixed addFixedIp Function IP Allocation Exhaustion Remote DoS
Folsom
OSVDB ID: 93133 OpenStack Nova signing_dir Permission Weakness Forged Token Generation
Grizzly
OSVDB ID: 93133 OpenStack Nova signing_dir Permission Weakness Forged Token Generation
Unspecified
OSVDB ID: 93453 OpenStack Nova Crafted qcow2 Image Disk Consumption DoS
OpenStack Image Registry and Delivery Service Watch-list
2012.2
OSVDB ID: 87248 OpenStack Backend Storage Repository Registery Permission Verification Arbitrary Virtual Image Deletion
2012.1
OSVDB ID: 87248 OpenStack Backend Storage Repository Registery Permission Verification Arbitrary Virtual Image Deletion
Keystone Watch-list
Unspecified
OSVDB ID: 89998 OpenStack Keystone Invalid Token Request Logging Disk Consumption Remote DoS
OSVDB ID: 93134 OpenStack Keystone API User Deletion Session Token Persistence Weakness
2012.2.1
OSVDB ID: 90193 OpenStack Keystone Crafted HTTP Request Handling Memory Exhaustion Remote DoS
Folsom
OSVDB ID: 91532 OpenStack Keystone Online Verification PKI Token Revocation Check Bypass
Unspecified
OSVDB ID: 92841 OpenStack Keystone Debug Logs LDAP Password Plaintext Local Disclosure
Unspecified
OSVDB ID: 92869 OpenStack Keystone Command Line Process Listing Local Credential Disclosure
Unspecified
Folsom (2012.2)
OSVDB ID: 93511 OpenStack Keystone Concurrent Crafted HTTP Request Handling Remote DoS
2013.1 (Grizzly)
OSVDB ID: 93651 OpenStack Keystone user-password-update Plaintext Local Password Disclosure
Folsom (2012.2)
OSVDB ID: 93726 OpenStack Keystone PKI Token Expiration Check Weakness
Folsom
OSVDB ID: 94229 OpenStack LDAP Backend Passwordless Authentication Bypass
Grizzly
OSVDB ID: 94229 OpenStack LDAP Backend Passwordless Authentication Bypass



The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2002 - 2013 Open Sourced Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use